openvz
KQL Cafe | Session 26 | Guest: Truvis Thornton | August 2024
0:00 Welcome to #KQLCafe
What’s new in #kql
1:47 Log Analytics Simple Update
3:09 Detect compromised #rdp with #xdr
5:56 #Hunting for #copilot activities
7:48 Detect outdated devices from SigninLogs
9:06 Steven Lim on #kqlsearch
10:12 Summary Rules in #sentinel
Our KQL Guest
18:32 Truvis Thornton
21:02 AuditD Config
29:05 AuditD Log Structure
32:04 Parser Building
36:00 DFIR Functions
40:31 Demo
What did you do with KQL this month
1:07:09 OneDrive and SharePoint downloads over the API
1:22:02 #KustoCon announcement 8th of November
[ad_2]
source